Coldcard Exploit Empties $114 Million in Bitcoin, Shaking Trust in Hardware Wallets

Stylized Bitcoin coin illuminated by golden light hovering above cracked glass panels with holographic glitches.

Tokens mentioned in this article:

David E | BITCOIN | 1 week ago

$114 Million Gone: Wallets Emptied Fast Over the past week, a major security flaw in the Coldcard hardware wallet has led to the theft of nearly 1,816 bitcoin—valued at around $114 million—across more than 5,200 addresses.

$114 Million Gone: Wallets Emptied Fast

Over the past week, a major security flaw in the Coldcard hardware wallet has led to the theft of nearly 1,816 bitcoin—valued at around $114 million—across more than 5,200 addresses. The attack began on July 30 with a rapid sweep that drained 1,083 BTC from 1,196 wallets in just 41 minutes. Subsequent waves over the weekend pushed total observed losses even higher, as attackers repeatedly targeted vulnerable addresses.

The vulnerability traces back to a March 2021 firmware build where Coldcard devices created new wallets using a predictable software-based random number generator instead of the device’s secure hardware chip. This made it possible for attackers to anticipate wallet seeds and drain funds held by unsuspecting users. Coinkite, the Canadian company behind Coldcard, responded by releasing emergency firmware updates and urging users to move their bitcoin to new wallets generated with fresh seeds.

On paper, hardware wallets are designed to be safer than exchanges, but this exploit has upended that assumption for thousands of bitcoin holders.

Replace-by-Fee Trick Fuels Draining Spree

Attackers didn’t just rely on the flawed random number generator—they also used Bitcoin’s replace-by-fee (RBF) feature to maximize their haul. RBF allows pending transactions to be overwritten if a higher fee is offered. By leveraging this capability, hackers could outpace legitimate user attempts to rescue their funds once news of the exploit spread. In four distinct waves since July 30, each sweep carefully targeted single-key addresses created by affected Coldcard devices.

None of the first three attack waves touched multisignature wallets, highlighting how the flaw was isolated to single-key setups.

Bitcoin Reserves Spike as Panic Grows

The scale and speed of the exploit triggered a visible reaction across the broader Bitcoin ecosystem. According to coindesk.com, on July 31—the day after the first sweep—daily bitcoin deposits to exchanges in amounts under 10 BTC soared to 7,300 BTC, marking the highest level since February 6. At the same time, CryptoQuant data showed exchange reserves climbing from 2.706 million BTC on July 30 to 2.718 million BTC shortly after.

This surge in exchange activity contrasts sharply with investor behavior during previous crises like FTX’s collapse in November 2022, when users pulled coins off exchanges en masse for self-custody. Now, shaken by a self-custody failure, many are moving assets back onto centralized platforms for perceived safety. The number of active daily bitcoin addresses also spiked dramatically—from 645,000 on July 30 to nearly one million on July 31—the highest since December of last year.

Price Slides as Exploit Drags On

The market has not been immune to these developments. As the Coldcard hack entered its fifth day, bitcoin’s price fell by 1.5% over a 24-hour period to $62,595 while ether dropped nearly 2% to $1,842. The CoinDesk DeFi Select Index registered an even steeper decline of 2.5%. Notably, bitcoin’s price slipped below its closely watched 200-week simple moving average—which currently sits above $63,000—adding technical pressure amid ongoing uncertainty about wallet security.

While solo miners have enjoyed rare windfalls—such as one miner who claimed block rewards worth roughly $199,300 early Monday—the broader sentiment among long-term holders has soured as years of savings vanished overnight due to a firmware oversight.

It’s unclear how quickly confidence in hardware wallets will recover or whether this episode will drive lasting changes in how individuals secure their digital assets.

Top Takeaways

  • The Coldcard exploit began July 30, 2024, draining 1,816 BTC (~$114 million) from over 5,200 addresses in four waves.
  • The vulnerability traces to a March 2021 firmware bug that used a predictable software random number generator for wallet seeds.
  • On July 31, daily bitcoin deposits to exchanges in transactions under 10 BTC spiked to 7,300 BTC, the highest in months.

What could still change

If the ongoing fourth wave of Coldcard wallet sweeps, which began early Monday and had already drained about 1,816 bitcoin from over 5,200 addresses as of July 30, continues or intensifies, immediate further losses for affected holders remain possible and could drive additional spikes in bitcoin deposits to exchanges, as seen with the 7,300 BTC in sub-10 BTC transactions recorded on July 31.

About the Author

David E

David E

Writer – DeFi & crypto markets

With a keen interest in decentralized finance and digital asset markets, David closely monitors Layer 1 and Layer 2 protocol developments. His articles break down market movements, token launches and governance issues shaping today's crypto landscape.